[tor-relays] connlimit: better to use "DROP" or "REJECT --reject-with tcp-reset"?

Toralf Förster toralf.foerster at gmx.de
Sun Jan 21 11:34:46 UTC 2018


On 01/11/2018 02:10 AM, teor wrote:
> So if you're going to do this, please set a much higher limit than 2.
> I would suggest at least 4, but 10 or more is better.
> 
> You might be able to set it higher if you put a limit on repeated
> connection attempts.
 
The simple approach (allowing 8 syn requests from an address at ORport and at DirPort respectively) worked flawlessley for a while - just few dozen/hundreds DROPs per hour. Since yesterday however I get > 100K DROPs per hour.

Could a side effect of that traffic be that I lost the Exit flag ?

-- 
Toralf
PGP C4EACDDE 0076E94E

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 260 bytes
Desc: OpenPGP digital signature
URL: <http://lists.torproject.org/pipermail/tor-relays/attachments/20180121/fc31c069/attachment-0001.sig>


More information about the tor-relays mailing list